Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Advanced Guestbook 2.4.4 Persistent XSS via Smilies
Vulnerability Description
Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field, which executes when administrators view the smilies tab.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Ampps Advanced Guestbook 跨站脚本漏洞
Vulnerability Description
Ampps Advanced Guestbook是印度Ampps公司的一个提供访客留言发布与管理功能的网站留言板系统。 Ampps Advanced Guestbook 2.4.4版本存在跨站脚本漏洞,该漏洞源于表情符号管理界面存在持久型跨站脚本,可能导致经过身份验证的攻击者通过操纵s_emotion参数注入恶意脚本。
CVSS Information
N/A
Vulnerability Type
N/A